Cookie Policy
Last updated: 8 August 2026
1. What this page covers
Cookies are small text files a website stores on your device; Energicore also uses similar browser storage where a vendor's tooling requires it. The identifiers they contain can be personal data, which is why this page exists: it names every cookie we set, what each one is for, how long it lasts, and how you stay in control.
2. Essential cookies
These are set on every visit because the site cannot function without them: one remembers your cookie choice itself, the others keep you signed in. The law does not require consent for strictly necessary cookies, and the banner does not ask for it.
| Cookie | Set by | What it does | Lasts |
|---|---|---|---|
| ec_cookie_consent | Energicore | Records the answer you gave in the cookie banner, so we neither ask again nor load analytics you refused. | 1 year |
| better-auth.session_token | Energicore | Keeps you signed in to your account. | Until it expires or you sign out |
| better-auth.session_data | Energicore | A short-lived cached copy of your session, so signed-in pages load without a database round trip. | 5 minutes |
On production hosts the sign-in cookies carry a __Secure- prefix and are shared across Energicore subdomains, so signing in once works across the platform.
3. Analytics cookies, only with your consent
These are set only after you press Accept in the cookie banner. If you press Reject, or ignore the banner entirely, none of them are set and the tools that use them are not loaded.
| Cookie | Set by | What it does | Lasts |
|---|---|---|---|
| _ga and _ga_* | Google Analytics | Distinguishes visitors so we can measure how our public marketing pages are used. | Up to 2 years |
| ph_* | PostHog (EU-hosted) | Product analytics: which features are used and where the platform fails people, so we can improve it. | Up to 1 year |
Google Analytics runs on our public marketing pages only, never on signed-in pages where a property or a person is identified. PostHog is hosted in the European Union. Both providers, including where their processing happens, are listed on our Subprocessors page.
4. Giving, refusing and withdrawing consent
- The banner: On your first visit the banner offers Accept, Reject and Customise. Rejecting takes a single press, exactly like accepting; we never make refusing the harder path. Customise lists each category and lets you switch analytics on or off directly. Nothing analytics-related loads until you choose, and rejecting never limits what the site can do.
- Changing your mind: Reopen the banner and change your answer at any time: . The same control sits in the footer of every page that has one. Withdrawing consent stops analytics collection and removes the analytics cookies we are able to remove from your browser.
- Your browser: You can also block or delete cookies in your browser settings. Blocking the essential cookies will stop sign-in from working.
5. Changes, related documents and contact
When the cookies we set change, this page changes with them and the date at the top is updated. How we handle personal data generally, including your rights and how to exercise them, is set out in our Privacy Policy.
Questions about anything on this page: hello@energicore.app.